3 ms·
Well, there's at least one glaring security issue that should be obvious to any Rails developer.
by danieldon 16y ago
Well, there's at least one glaring security issue that should be obvious to any Rails developer.
- uptown 16y agoDid you remember to bring enough knowledge to share with the rest of the class? What glaring issue are you referring to?
- patio11 16y agoThis is the problem with public disclosure: I could tell you, but it would practically write exploit code which you could point at any one of the "Try Diaspora now!" sites popping up and do very bad things. Here, let me tell you what isn't a problem: you cannot type "system('rm -rf /')" into their username field on the signup form and wipe any machine with Diaspora installed because some idiot passed untrusted user input straight to exec. But if that were a problem, do you understand why mentioning publicly "Hey, the username field is passed straight to exec... that's sort of bad." is a bad idea? Because that lets any idiot immediately create wipe_arbitrary_diaspora_install.rb There are several vulnerabilities in Diaspora right now. They allow very bad things. There are multiple public Diaspora installations. They are all vulnerable to very bad things. I think releasing this was very, very premature.
- shajith 16y agoThere is now a security email ID you can contact: exploits@joindiaspora.com It's been added to the README at http://github.com/diaspora/diaspora http://github.com/diaspora/diaspora
- danieldon 16y agoIt's interesting to see people on HN downvoting some for being responsible with information while upvoting those who advocate irresponsible disclosure.